Trust · Security

Security evidence, without theater.

Insurf maintains a security program for its public site, private pilots, and internal operating systems. This page is a public summary; customers receive contract and evidence packets through approved diligence channels.

Controls

Operating posture.

The live program is intentionally conservative: high-risk paths fail closed until evidence exists.

Access
Founder/admin access is MFA-oriented and reviewed for production paths; Vanta now monitors Google Workspace and GitHub evidence.
Code
GitHub is connected to Vanta for repository and Dependabot evidence. Branch protection enforcement remains an open remediation item until GitHub settings are updated.
Cloud
AWS is the intended covered cloud boundary for S3, KMS, Textract, and logging. Vanta AWS monitoring awaits the CloudFormation-created VantaAuditorRoleArn.
Vendors
The PHI path is limited to AWS, Vercel, Neon, and OpenAI unless a signed customer agreement authorizes more.
Boundaries

What is not claimed.

  • Insurf does not claim SOC 2 certification or a completed SOC 2 report.
  • Insurf does not claim HIPAA certification; HIPAA readiness depends on BAAs, policies, and launch controls.
  • Public demos use synthetic or redacted material, not production PHI.
  • Any vulnerability disclosure should avoid accessing customer data, modifying data, or disrupting service.